
Executive summary
The cyberspace threat environment continues to be dominated by four reinforcing patterns: ransomware and extortion, identity and credential compromise, rapid exploitation of known internet-facing vulnerabilities, and abuse of trusted technology providers to reach downstream victims. None of these requires novel capability. They persist because they are cheap, repeatable, and effective against organisations with incomplete asset inventories and inconsistent multi-factor authentication. UPDATE, 3 SEPTEMBER 2026: Recorded Future research places Latin America and the Caribbean at the centre of this pattern, reporting 452 ransomware incidents affecting organisations in the region during 2025. Brazil and Mexico absorbed the largest shares, with Argentina, Colombia, and Chile following. The most affected sectors were manufacturing, professional and business services, government and public administration, financial services, and healthcare. Beyond ransomware, the research highlights infostealer malware, hacktivist activity, business email compromise, and state-linked espionage as concurrent pressures on the same defensive base. The most consequential finding for regional clients is not the incident count but the cause profile. Weak or absent multi-factor authentication, legacy and unsupported systems, limited security staffing, and slow patching of internet-facing infrastructure explain the majority of successful intrusions. These are budget and process problems rather than technology gaps, which means the exposure is addressable but structurally persistent across the forecast horizon.
- Ransomware and extortion
- 5/5
- Identity and credential compromise
- 5/5
- Legacy and unsupported systems
- 5/5
- Edge-device and known-vulnerability exploitation
- 4/5
- Business email compromise
- 4/5
- Hacktivism and disruption
- 3/5
- State-linked espionage
- 4/5
Relative severity across the 12-month forecast horizon, updated 3 September 2026 for the Latin America and Caribbean picture.
Key judgments
- Ransomware remains the highest-volume material threat to regional organisations; Recorded Future reported 452 incidents affecting Latin America and the Caribbean in 2025.
- Brazil and Mexico carry the largest national exposure by incident volume, reflecting economy size, digitalisation, and attack-surface breadth rather than uniquely weak defences.
- Manufacturing, professional services, government, financial services, and healthcare are the most targeted sectors; each combines operational urgency with legacy dependency, which raises extortion leverage.
- Identity compromise is the dominant initial access vector. Infostealer-harvested credentials, session-token theft, and MFA gaps convert commodity malware into enterprise intrusion.
- Legacy and unsupported systems, particularly in government and healthcare, extend recovery times and increase the probability of paying extortion demands.
- Internet-facing edge devices - VPN appliances, firewalls, routers, and file-transfer systems - remain the most reliably exploited entry point across the region.
- Hacktivist and politically motivated activity increases around elections and social unrest, adding availability and defacement risk on top of criminal extortion.
- State-linked espionage against government, energy, and telecommunications targets continues in parallel with criminal activity and frequently uses the same unpatched infrastructure.
- Business email compromise remains the highest-loss-per-incident financial threat for mid-sized regional firms and is under-reported relative to ransomware.
The full assessment, including sourcing, analytic confidence statements, and indicators and warnings, is available in the downloadable PDF.
Download full PDF

